Principal Detection Engineer (Remote, GBR)

Crowdstrke
United Kingdom
Workplace: RemoteFull timeFunction: Communications, PR & CommunitySkills: ["Communication","Influence","Technical leadership","Cross-team alignment","Technical coaching"]

Own cross-domain detection strategy across endpoint, cloud, NG-SIEM, identity, and SaaS security, turning full-platform visibility into coherent threat detection coverage. Build high-fidelity correlation detections with entity resolution, temporal reasoning, and behavioral layering to deliver high-severity, low-false-positive results via Platform IOAs. Use threat intel to prioritize investments, coordinate multi-team detection delivery, and apply AI/LLM to accelerate gap analysis and workflow automation while coaching engineers across the function.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Crowdstrke
Crowdstrke
1 day ago

Principal Detection Engineer (Remote, GBR)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Own cross-domain detection strategy across endpoint, cloud, NG-SIEM, identity, and SaaS security, turning full-platform visibility into coherent threat detection coverage. Build high-fidelity correlation detections with entity resolution, temporal reasoning, and behavioral layering to deliver high-severity, low-false-positive results via Platform IOAs. Use threat intel to prioritize investments, coordinate multi-team detection delivery, and apply AI/LLM to accelerate gap analysis and workflow automation while coaching engineers across the function.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Communications, PR & Community
Seniority: Sr. Manager level

Key Responsibilities

  • •Own cross-domain detection strategy and maintain visibility into detection work across endpoint, cloud, NG-SIEM, identity, SaaS security, and FEM.
  • •Design high-fidelity correlation detections that join signals across domains using entity resolution, temporal reasoning, and behavioral layering.
  • •Drive threat-informed prioritization by monitoring internal/external intel sources and translating threat shifts into detection investment decisions.
  • •Coordinate cross-team detection development so scenarios ship with coherent coverage across all relevant surfaces simultaneously.
  • •Coach and enable detection engineers via technical direction, PR reviews, hands-on coaching, and co-development on hard problems.

Pay and Benefits

Perks:Wellness StipendPaid Leave

Key Requirements

  • •Extensive experience writing production detection content across multiple platforms or data domains, with strong understanding of telemetry sources and where coverage breaks down.
  • •Ability to think across domains for threats spanning endpoint, cloud, identity, SaaS, and runtime, including designing or contributing to correlated detections across boundaries.
  • •Strong fluency in the threat landscape (actors, campaigns, and TTPs) and the ability to translate threat intelligence into detection requirements and prioritization decisions.
  • •Experience with the detection content lifecycle at scale, including rule aging, false-positive drift, performance cost, and deprecation decisions while maintaining measurable detection quality.
  • •Experience applying AI/LLM to security workflows to enhance decision-making and streamline processes, plus strong communication, technical leadership, and influence across teams.
Experience:CybersecurityEDRSIEMDetection engineeringDistributed systems
Skills:CommunicationInfluenceTechnical leadershipCross-team alignmentTechnical coaching
Tech Stack:AWSGCPAzureKubernetesNG-SIEMAdaptive ShieldPlatform IOAs (CDE)MITRE ATT&CKAILLMEntity resolutionTemporal reasoningBehavioral layering

Company Brief

Crowdstrke
Provides cloud-native endpoint protection, threat intelligence, and security operations solutions that prevent breaches and stop sophisticated cyberattacks across endpoints, cloud workloads, identity, and APIs for enterprises worldwide.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Sunnyvale, United States
Founded: 2011
Glassdoor
Glassdoor: 4.4
WebsiteLinkedIn